securityonline.info 7/30/2026, 7:20:41 AM · external

North Korean Hackers Exploit Fake Zoom Calls to Steal Crypto Data

North Korean Hackers Exploit Fake Zoom Calls to Steal Crypto Data
CyberSIXT Evidence Panel
Primary Source jumpsec.com
Threat Actor

A recent report by JUMPSEC highlights an active phishing campaign by the North Korean BlueNoroff group, targeting cryptocurrency staff through fake Zoom and Teams meetings. The attack relies on hijacked Telegram accounts to send genuine-looking invites, leading victims to a rogue platform that extracts sensitive information like crypto wallet details.

The phishing kit operates silently, employing AI-generated videos to simulate live interactions and a ClickFix payload to install malware on both Windows and macOS systems. Notably, this campaign leveraged over 60 hostnames and demonstrated sophisticated techniques typical of state-sponsored cyber operations. Users are advised to verify meeting invites through independent channels and scrutinize URLs before engagement.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline